Evillm
7 exploits
Active since Jul 2020
React Server Components <19.2.0 - RCE
CVSS 10.0
Roundcube Webmail < 1.5.10 and 1.6.x < 1.6.11 - Authenticated Remote Code Execution via PHP Object Deserialization
CVSS 9.9
BentoML >=1.3.4 <1.4.3 - Unauthenticated Remote Code Execution via Insecure Deserialization
CVSS 9.8
WordPress WP Time Capsule Arbitrary File Upload to RCE
CVSS 9.8
body-parser < 1.20.3 - Denial of Service via URL Encoding
CVSS 7.5
Media Library Assistant <3.09 - RCE
CVSS 9.8
Apache Airflow < 1.10.10 - OS Command Injection via CeleryExecutor
CVSS 9.8